Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Royce Williams

@tychotithonus@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Just doing my undue diligence.

ISP vet (was AS7782, now AS8047), password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed = probably stole you from someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Suggestions welcome!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning by a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers w/heat of 400B suns

❤️:⚛👨‍👩‍👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!

3632 Followers
3891 Following
50 Posts
Joined April 26, 2022
Stuff:
https://www.techsolvency.com/roycewilliams/mastodon
Keybase:
https://keybase.io/royce
GitHub:
https://github.com/roycewilliams
LinkedIn:
https://www.linkedin.com/in/roycewilliams
Gravatar:
https://gravatar.com/tychotithonus
Not "dehashed"!:
https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1d ago
The mocktail page of this menu is headed "Absence of Proof".
5
1
1
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 4w ago
Boosted by @GroupNebula563@mastodon.social
Having this printed out on the wall behind where I normally join calls, and being able to point to it when its bingo square comes up in discussion, continues to pay dividends, @mcc@mastodon.social Edit: original post (credit where due!): https://mastodon.social/@mcc/115079977230405147
900
0
392
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 5d ago
So the Transcend flash-IDE drives (to replace spinning rust in legacy computers) ... pretend they support SMART, but all the values are zero, so you can't tell actual power-on hours, etc.?
6
0
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

RE: @yaelwrites@mastodon.social

New security goals unlocked. "So secure people think it's fake" 💡

23
0
9
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

RE: @campuscodi@mastodon.social

Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic "starve it, then declare it ineffective" tactic. 😠

11
0
10
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
Just imagine the cognitive dissonance and/or agony of the person who had to write this copy.
15
2
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

Bring back the Password Village at DEF CON!

They help so many practitioners a year bootstrap from having zero cracking clue to actually getting it. That team works their butts off the whole con, often with minimal or zero external sponsorship, paying for a lot of stuff totally out of pocket, year after year, just to grow the practice and see the light bulb go off over somebody's head (when they realize that it's not just all about rainbow tables and how many GPUs you have).

And the effort they spend crafting the CMIYC cracking CTF ... It is difficult to explain to outsiders how deeply they understand their craft. It is a love letter to the breadth and depth of password cracking.

If there is any team that embodies what a practitioner's conference is supposed to be about, it is @CrackMeIfYouCan@infosec.exchange.

Bring back the Password Village!

#DEFCON34 #DEFCON

9
0
7
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
Posited corollary 2: Sinclair's "It is difficult to get a man to understand something when his salary depends on his not understanding it" ... is an existential security threat that will now more rapidly metastasize if left unchecked. 3/3
10
1
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
Put another way: Dan Geer's definition of security ("the absence of unmitigatable surprise") is facing a progression of machines that increasingly unearth all possible surprises. A threat ... and an opportunity.
9
0
3
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
Posited corollary: @wendynather@infosec.exchange's "security poverty line" has always had a companion threshold: a "security realism poverty line", the divide between organizations that have the political will to mercilessly and constantly reduce the gap between what they think is true (or want to be true, or have budgeted to be true) and what is actually true ... and those that don't, whether due to budget or competence or competing incentives. And the AI-accelerated death of security through all-cause obscurity (described above) is magnifying the gap on either side of that line. Sinclair's "It is difficult to get a man to understand something when his salary depends on his not understanding it" ... is an existential security threat that will now more rapidly metastasize if left unchecked.
9
1
4
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
"It wasn't on purpose, that was my lead generation platform." "Feel free to convey to your food chain that that's what lost you the sale."
8
0
1
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

No shade or anything, but I do not understand the urge to wear an Emirates shirt. It just looks like you like an airline.

7
2
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

That's a new one. (Voicemail transcription)

6
0
1
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @danluu@mastodon.social
@danluu@mastodon.social Fascinating! Have you seen the work that Jordan Hubbard (FreeBSD / Apple / NVIDIA) is doing on nanolang, to tackle efficient token use in a programming language? https://github.com/jordanhubbard/nanolang
3
1
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
I first read this book 20 years ago, and that story still literally chokes me up a little. It's what gets me up in the morning.
4
0
1
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @_bapt_@mastodon.social
@bapt@mastodon.social @trashheap@tech.lgbt Really appreciate the effort, it's clear the teams put a lot of thought into it.
4
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

All part of this Turing-complete breakfast!

1
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @vermaden@mastodon.bsd.cafe
@vermaden@mastodon.bsd.cafe So many of these details appear to be requiring people to construct them for themselves, which is not the standard I have come to expect from the project, so I'm not sure what has changed.
2
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @seanm@infosec.exchange
@seanm@infosec.exchange I've read it twice and I still don't know what they mean by that part.
2
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago

Hey, cracking folk ... did you know that Hashtopolis 1.0.0 was just released?

https://github.com/hashtopolis/server/releases/tag/v1.0.0

Total redesign, SPA based on TailwindCSS, Postgres support, Docker driven, full REST API, OAUTH2, improved supertasks, full UTF-8 support.

Did a fresh install, working great so far!

Thanks to @s3inlc@infosec.exchange and team!

1
0
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
@ANC_Historian@alaskan.social (And that year in the description jibes with the plate, that's a 1962 plate with 1964 sticker (yellow, bottom left) and 1963 tab (blue, bottom right)
1
2
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @catc0n@infosec.exchange
@catc0n@infosec.exchange Oooh, fair point - would be good to see the lifecycle / dwell axis alongside the data over time. Hmm!
1
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange I mean, naively, could these just be the ones that were shared somewhere else, like on Reddit or on forums or something?
1
3
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
So is Google's new "Selfie Sign-In" just a single factor? And it looks like it's not available if you have Advanced Protection enabled? https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/ Why doesn't the announcement mention any of this?
1
5
2
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @corq@infosec.exchange
@corq@infosec.exchange If I recall correctly, he played this when he was a guest star on WKRP!
0
1
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
The purpose of Stauer, Danbury Mint, Bradford Exchange, Lillian Vernon, the various "coin exchanges" / "mints", etc is to extract 90% markup from people who can't shop in person anymore and/or have no sense of actual market value. And newspapers, magazines, and TV stations that run their ads are complicit in the victimization of a vulnerable population.
0
2
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @ANC_Historian@alaskan.social
@ANC_Historian@alaskan.social Anything that looks potentially unusual is absolutely in scope, this is a fantastic find!
0
1
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @dpp@mastodon.social
@dpp@mastodon.social I see what you did there
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 2d ago
Replying to on mastodon.social
@lzg@mastodon.social /me nods in Alaskan
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @gnomon@mastodon.social
@gnomon@mastodon.social No lies detected!
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Looking forward the day when a RU-associated threat actor gets the code name "BOUNTY BEAR" https://m.youtube.com/watch?v=kKhzsx2gVgM (and RIP Sam Neill)
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 2d ago
Replying to @buherator@infosec.place
@buherator@infosec.place Wow that's really thorough, this will be useful! Though I was expecting there to be some for operating systems as well, though that seems like a different kind of problem in some ways.
0
1
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
It's gonna be ... hard to get one of this year's DEF CON badges for the security-key collection.
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @sarahjamielewis@mastodon.social
@sarahjamielewis@mastodon.social Hey, cool! Note that we couldn't reverse anything here - had to use classic cracking, trying lots of host/domain combos until we got exact hits. Kudos to @s3inlc@infosec.exchange for getting some really hard ones at the end!
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @fugueish@wandering.shop
@fugueish@wandering.shop I had seen people linking to it but didn't know what it was a review of. I literally just got home from seeing it, and ... she's not wrong. Hm.
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Between Hoyt Axton's "Della and the Dealer" and Conway Twitty's "Saturday Night Special", I seem to have an affinity for stories where good folk have to get tough with the bad folk in defense of a cutie ... and then high-tail it for the hinterlands with said cutie.
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @neurovagrant@masto.deoan.org
@neurovagrant@masto.deoan.org Huh. Naively, feels like a proactive legal play, like it makes certain kinds of charges or lawsuits possible later?
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Update on the FreeBSD ports cleanup after someone committed a 150M blob of the Linux Copilot CLI: https://people.freebsd.org/~kevans/core/ports-freeze-final.txt.asc Good as far as it goes, especiallly the striving for transparency, reproducibility, and minimizing downstream impacts. Notably missing, however: an explanation of how it happened in the first placeconcrete steps that will be taken to prevent it from happen again #FreeBSD
0
2
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 2mo ago
Replying to @ChasMusic@ohai.social
@ChasMusic@ohai.social in many cases yes, and in their specific case, it does look like it.
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 2mo ago
Replying to @ChasMusic@ohai.social
@ChasMusic@ohai.social Some offer only one, some offer both, not share what happens if you've got both and you register/integrate one of them but not the other. It's a good question.
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
All of the major third parties you rely on ... are constantly trying to reduce their dependency on third parties. Some dependencies are inevitable. Which of your third parties can prove they are actively reducing entire classes of the risk they expose you to?
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Well, that's disappointing.
0
1
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Just got my first "YouTube detected this screenshot" Android notification. 😱
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 3w ago
Replying to @krypt3ia@infosec.exchange
@krypt3ia@infosec.exchange 🍞 🍚 🔫 🧻
0
1
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @tychotithonus@infosec.exchange
@ANC_Historian@alaskan.social Actually if it was 1965, their sticker is expired. 😉 Or else it's really 1964 ...
0
0
0
0
Open post
Royce Williams @tychotithonus@infosec.exchange
· 1mo ago
Replying to @_bapt_@mastodon.social
@bapt@mastodon.social That is good to know, though just for optics purposes I think it should be much more overly explicit, like in its own section of the write-up, and in more detail. I know everyone means well, but pushing prevention as a repeated public messaging element is an opportunity for improvement. @trashheap@tech.lgbt
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:35:22 UTC